Issue 7142: Prevent respawn of "remote self" items
[friendica.git/.git] / mod / cal.php
1 <?php
2 /**
3  * @file mod/cal.php
4  * @brief The calendar module
5  *      This calendar is for profile visitors and contains only the events
6  *      of the profile owner
7  */
8
9 use Friendica\App;
10 use Friendica\Content\Feature;
11 use Friendica\Content\Nav;
12 use Friendica\Content\Widget;
13 use Friendica\Core\Config;
14 use Friendica\Core\L10n;
15 use Friendica\Core\Renderer;
16 use Friendica\Core\System;
17 use Friendica\Database\DBA;
18 use Friendica\Model\Contact;
19 use Friendica\Model\Event;
20 use Friendica\Model\Group;
21 use Friendica\Model\Item;
22 use Friendica\Model\Profile;
23 use Friendica\Protocol\DFRN;
24 use Friendica\Util\DateTimeFormat;
25 use Friendica\Util\Temporal;
26
27 function cal_init(App $a)
28 {
29         if ($a->argc > 1) {
30                 DFRN::autoRedir($a, $a->argv[1]);
31         }
32
33         if (Config::get('system', 'block_public') && !local_user() && !remote_user()) {
34                 throw new \Friendica\Network\HTTPException\ForbiddenException(L10n::t('Access denied.'));
35         }
36
37         if ($a->argc < 2) {
38                 throw new \Friendica\Network\HTTPException\ForbiddenException(L10n::t('Access denied.'));
39         }
40
41         Nav::setSelected('events');
42
43         $nick = $a->argv[1];
44         $user = DBA::selectFirst('user', [], ['nickname' => $nick, 'blocked' => false]);
45         if (!DBA::isResult($user)) {
46                 throw new \Friendica\Network\HTTPException\NotFoundException();
47         }
48
49         $a->data['user'] = $user;
50         $a->profile_uid = $user['uid'];
51
52         // if it's a json request abort here becaus we don't
53         // need the widget data
54         if (!empty($a->argv[2]) && ($a->argv[2] === 'json')) {
55                 return;
56         }
57
58         $profile = Profile::getByNickname($nick, $a->profile_uid);
59
60         $account_type = Contact::getAccountType($profile);
61
62         $tpl = Renderer::getMarkupTemplate("widget/vcard.tpl");
63
64         $vcard_widget = Renderer::replaceMacros($tpl, [
65                 '$name' => $profile['name'],
66                 '$photo' => $profile['photo'],
67                 '$addr' => (($profile['addr'] != "") ? $profile['addr'] : ""),
68                 '$account_type' => $account_type,
69                 '$pdesc' => (($profile['pdesc'] != "") ? $profile['pdesc'] : ""),
70         ]);
71
72         $cal_widget = Widget\CalendarExport::getHTML();
73
74         if (empty($a->page['aside'])) {
75                 $a->page['aside'] = '';
76         }
77
78         $a->page['aside'] .= $vcard_widget;
79         $a->page['aside'] .= $cal_widget;
80
81         return;
82 }
83
84 function cal_content(App $a)
85 {
86         Nav::setSelected('events');
87
88         // get the translation strings for the callendar
89         $i18n = Event::getStrings();
90
91         $htpl = Renderer::getMarkupTemplate('event_head.tpl');
92         $a->page['htmlhead'] .= Renderer::replaceMacros($htpl, [
93                 '$module_url' => '/cal/' . $a->data['user']['nickname'],
94                 '$modparams' => 2,
95                 '$i18n' => $i18n,
96         ]);
97
98         $mode = 'view';
99         $y = 0;
100         $m = 0;
101         $ignored = (!empty($_REQUEST['ignored']) ? intval($_REQUEST['ignored']) : 0);
102
103         $format = 'ical';
104         if ($a->argc == 4 && $a->argv[2] == 'export') {
105                 $mode = 'export';
106                 $format = $a->argv[3];
107         }
108
109         // Setup permissions structures
110         $remote_contact = false;
111         $contact_id = 0;
112
113         $owner_uid = $a->data['user']['uid'];
114         $nick = $a->data['user']['nickname'];
115
116         if (!empty($_SESSION['remote']) && is_array($_SESSION['remote'])) {
117                 foreach ($_SESSION['remote'] as $v) {
118                         if ($v['uid'] == $a->profile['profile_uid']) {
119                                 $contact_id = $v['cid'];
120                                 break;
121                         }
122                 }
123         }
124
125         $groups = [];
126         if ($contact_id) {
127                 $groups = Group::getIdsByContactId($contact_id);
128                 $r = q("SELECT * FROM `contact` WHERE `id` = %d AND `uid` = %d LIMIT 1",
129                         intval($contact_id),
130                         intval($a->profile['profile_uid'])
131                 );
132                 if (DBA::isResult($r)) {
133                         $remote_contact = true;
134                 }
135         }
136
137         $is_owner = local_user() == $a->profile['profile_uid'];
138
139         if ($a->profile['hidewall'] && !$is_owner && !$remote_contact) {
140                 notice(L10n::t('Access to this profile has been restricted.') . EOL);
141                 return;
142         }
143
144         // get the permissions
145         $sql_perms = Item::getPermissionsSQLByUserId($owner_uid, $remote_contact, $groups);
146         // we only want to have the events of the profile owner
147         $sql_extra = " AND `event`.`cid` = 0 " . $sql_perms;
148
149         // get the tab navigation bar
150         $tabs = Profile::getTabs($a, 'cal', false, $a->data['user']['nickname']);
151
152         // The view mode part is similiar to /mod/events.php
153         if ($mode == 'view') {
154                 $thisyear = DateTimeFormat::localNow('Y');
155                 $thismonth = DateTimeFormat::localNow('m');
156                 if (!$y) {
157                         $y = intval($thisyear);
158                 }
159
160                 if (!$m) {
161                         $m = intval($thismonth);
162                 }
163
164                 // Put some limits on dates. The PHP date functions don't seem to do so well before 1900.
165                 // An upper limit was chosen to keep search engines from exploring links millions of years in the future.
166
167                 if ($y < 1901) {
168                         $y = 1900;
169                 }
170
171                 if ($y > 2099) {
172                         $y = 2100;
173                 }
174
175                 $nextyear = $y;
176                 $nextmonth = $m + 1;
177                 if ($nextmonth > 12) {
178                         $nextmonth = 1;
179                         $nextyear ++;
180                 }
181
182                 $prevyear = $y;
183                 if ($m > 1) {
184                         $prevmonth = $m - 1;
185                 } else {
186                         $prevmonth = 12;
187                         $prevyear --;
188                 }
189
190                 $dim = Temporal::getDaysInMonth($y, $m);
191                 $start = sprintf('%d-%d-%d %d:%d:%d', $y, $m, 1, 0, 0, 0);
192                 $finish = sprintf('%d-%d-%d %d:%d:%d', $y, $m, $dim, 23, 59, 59);
193
194
195                 if (!empty($a->argv[2]) && ($a->argv[2] === 'json')) {
196                         if (!empty($_GET['start'])) {
197                                 $start = $_GET['start'];
198                         }
199
200                         if (!empty($_GET['end'])) {
201                                 $finish = $_GET['end'];
202                         }
203                 }
204
205                 $start = DateTimeFormat::utc($start);
206                 $finish = DateTimeFormat::utc($finish);
207
208                 $adjust_start = DateTimeFormat::local($start);
209                 $adjust_finish = DateTimeFormat::local($finish);
210
211                 // put the event parametes in an array so we can better transmit them
212                 $event_params = [
213                         'event_id'      => intval(defaults($_GET, 'id', 0)),
214                         'start'         => $start,
215                         'finish'        => $finish,
216                         'adjust_start'  => $adjust_start,
217                         'adjust_finish' => $adjust_finish,
218                         'ignore'        => $ignored,
219                 ];
220
221                 // get events by id or by date
222                 if ($event_params['event_id']) {
223                         $r = Event::getListById($owner_uid, $event_params['event_id'], $sql_extra);
224                 } else {
225                         $r = Event::getListByDate($owner_uid, $event_params, $sql_extra);
226                 }
227
228                 $links = [];
229
230                 if (DBA::isResult($r)) {
231                         $r = Event::sortByDate($r);
232                         foreach ($r as $rr) {
233                                 $j = $rr['adjust'] ? DateTimeFormat::local($rr['start'], 'j') : DateTimeFormat::utc($rr['start'], 'j');
234                                 if (empty($links[$j])) {
235                                         $links[$j] = System::baseUrl() . '/' . $a->cmd . '#link-' . $j;
236                                 }
237                         }
238                 }
239
240                 // transform the event in a usable array
241                 $events = Event::prepareListForTemplate($r);
242
243                 if (!empty($a->argv[2]) && ($a->argv[2] === 'json')) {
244                         echo json_encode($events);
245                         exit();
246                 }
247
248                 // links: array('href', 'text', 'extra css classes', 'title')
249                 if (!empty($_GET['id'])) {
250                         $tpl = Renderer::getMarkupTemplate("event.tpl");
251                 } else {
252 //                      if (Config::get('experimentals','new_calendar')==1){
253                         $tpl = Renderer::getMarkupTemplate("events_js.tpl");
254 //                      } else {
255 //                              $tpl = Renderer::getMarkupTemplate("events.tpl");
256 //                      }
257                 }
258
259                 // Get rid of dashes in key names, Smarty3 can't handle them
260                 foreach ($events as $key => $event) {
261                         $event_item = [];
262                         foreach ($event['item'] as $k => $v) {
263                                 $k = str_replace('-', '_', $k);
264                                 $event_item[$k] = $v;
265                         }
266                         $events[$key]['item'] = $event_item;
267                 }
268
269                 $o = Renderer::replaceMacros($tpl, [
270                         '$tabs' => $tabs,
271                         '$title' => L10n::t('Events'),
272                         '$view' => L10n::t('View'),
273                         '$previous' => [System::baseUrl() . "/events/$prevyear/$prevmonth", L10n::t('Previous'), '', ''],
274                         '$next' => [System::baseUrl() . "/events/$nextyear/$nextmonth", L10n::t('Next'), '', ''],
275                         '$calendar' => Temporal::getCalendarTable($y, $m, $links, ' eventcal'),
276                         '$events' => $events,
277                         "today" => L10n::t("today"),
278                         "month" => L10n::t("month"),
279                         "week" => L10n::t("week"),
280                         "day" => L10n::t("day"),
281                         "list" => L10n::t("list"),
282                 ]);
283
284                 if (!empty($_GET['id'])) {
285                         echo $o;
286                         exit();
287                 }
288
289                 return $o;
290         }
291
292         if ($mode == 'export') {
293                 if (!intval($owner_uid)) {
294                         notice(L10n::t('User not found'));
295                         return;
296                 }
297
298                 // Test permissions
299                 // Respect the export feature setting for all other /cal pages if it's not the own profile
300                 if ((local_user() !== intval($owner_uid)) && !Feature::isEnabled($owner_uid, "export_calendar")) {
301                         notice(L10n::t('Permission denied.') . EOL);
302                         $a->internalRedirect('cal/' . $nick);
303                 }
304
305                 // Get the export data by uid
306                 $evexport = Event::exportListByUserId($owner_uid, $format);
307
308                 if (!$evexport["success"]) {
309                         if ($evexport["content"]) {
310                                 notice(L10n::t('This calendar format is not supported'));
311                         } else {
312                                 notice(L10n::t('No exportable data found'));
313                         }
314
315                         // If it the own calendar return to the events page
316                         // otherwise to the profile calendar page
317                         if (local_user() === intval($owner_uid)) {
318                                 $return_path = "events";
319                         } else {
320                                 $return_path = "cal/" . $nick;
321                         }
322
323                         $a->internalRedirect($return_path);
324                 }
325
326                 // If nothing went wrong we can echo the export content
327                 if ($evexport["success"]) {
328                         header('Content-type: text/calendar');
329                         header('content-disposition: attachment; filename="' . L10n::t('calendar') . '-' . $nick . '.' . $evexport["extension"] . '"');
330                         echo $evexport["content"];
331                         exit();
332                 }
333
334                 return;
335         }
336 }